An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
appleprivacyletter.com
appleprivacyletter.com
Because of this decision (and the fact that my iPhone more-or-less facilitates poor habits throughout my life), I'm considering moving completely out of the Apple ecosystem.
Does anyone have any recommendations for replacements?
* On laptops: I have an X1 carbon extreme running linux, but it's entirely impratical to take outside of the house: it has terrible battery life and runs quite hot. I also cannot stand its trackpad. Is there any linux-capable device with an okay trackpad?
* On phones: are there any capable phones out there that aren't privacy nightmares? All I want is a phone with a long lasting battery that I can use with maps, a web browser, and texting.
* On cloud: I've considered executing on a NAS forever, but I'm unsure where to start.
Router: https://www.turris.com/en/omnia/overview/
Media Center: https://osmc.tv/vero/
Cloud (Use TrueNAS Scale): https://www.truenas.com/systems-overview/
Phone: https://www.pine64.org/pinephone/
Watch: https://pine64.com/product/pinetime-smartwatch-sealed/
Smart Thermostat: https://hestiapi.com/product/hestiapi-touch-one-free-shippin...
If you go this route all devices will be running Linux. The one OS route is kindof nice, hence the pinephone over open android alternatives (like Graphene OS).
I sorted from least to most technical. I also tried to pick the least technical challenging in each category. The Dell stuff should just work. The Phone will require some tinkering for the moment.
Or: Lenovo Yoga Convertible. My second device. I just don't do games. Or bigger data stuff on this machine. Some design work. Some photo and smaller video stuff. I love the flexibility of the convertible when working with PDF and doing annotations by hand.
Also, has anyone tried the FXtec phones? https://www.fxtec.com I am thinking about getting the FXtec pro1 version, which promises to get a decent UbuntuTouch support as well as lineageOS.
I feel that with the comeback of Vim, there might be a sufficient user base for devices that use the keyboard for most tasks. I miss the days, when I could send a text message without taking the phone out of my pocket.
Edit: Just found a relevant HN discussion: https://news.ycombinator.com/item?id=26659150
Guess, I'll dig out the old digital camera again, since that is a weak point for the pinephone. :-D
I have a maxed out xps and it is a downgrade in all respects but privacy. :/
I have X1C (not extreme) and it has excellent battery life with Linux. Consider using TLP (https://linrunner.de/tlp/), if you want to significantly improve your laptop power consumption.
In general, you need to balance budget, capacity requirements, and form factor. Old servers are often great. Big disks seem like a good idea, but for rebuild times going over 4TB is horrible.
However, unfortunately HDD prices right now are horrible...
Phone: Pixel with GrapheneOS or CalyxOS. In the future a Linux phone when the software improves.
I've seen this recommendation very often lately. As I am shopping for a new phone: Why is it that hardware directly from Google is recommended for putting another OS onto it (I've seen recommendations for LineageOS as well). What makes it better than any stock phone supported by LineageOS?
Phone-wise, there are many options to choose from. I like the idea behind the Teracube 2E[1], as they take some of the principles behind Framework and apply it to phones.
> On cloud: I've considered executing on a NAS forever, but I'm unsure where to start.
Depends on how much you want to tinker. You can't go wrong with a Raspberry Pi and some external harddrives, but there is also dedicated NAS equipment that requires less setup and maintenance, some of them are Linux based, as well.
My XPS 15 does about 6 hours (it's a maxed out i7) on Linux and 3 on Windows.
On cloud: Synology Diskstation is amazing. Only use it through a local VPN though.
edit: maps work (see reply)
I don't experience any issues using mapping apps on Android with microG instead of Google Play Services. Closed source navigation apps including Google Maps, HERE WeGo, and Magic Earth work just fine. Open source navigation apps like Organic Maps and OsmAnd also work with no problems.
For nas, synology is always a good brand.
Apple can (and likely will) say they won't do it and then do it anyway. It's a proprietary platform. They already have it, now. All they are claiming is an excuse not to be caught in a certain way they wouldn't like at a later point.
"Oh, nothing will happen to this [corrupt politician|naughty rich guy|corporation doing a thing I don't like], because they're all [bad thing]. It's all over already." :facepalm:
(Also, I couldn't read the original article because my work thinks it's spreading malware or something so I'm really only referring to the fatalism thing here, not Apple.)
Here is a true story for you:
Company X claimed users voice commands never left their devices. Then someone leaked recordings of people having sex, commiting crimes, etc recorded from X devices. This was brought up by media. For every concerned user there were ten apologist trying to justify this behaviour and a week later everyone forgot this ever happened.
I would really like to hear from people who sign this open letter, how they think about this. Should the internet be a free for all place without moderation? Where are the boundaries for moderation (if it has to exist), one-on-one versus group chat, public versus private chat?
To quote this open letter: “Apple is opening the door to broader abuses”. Wouldn't not doing anything open a different door to broader abuse?
Edit: I would really love an actual answer, since responses until now have been "but muh privacy". You can't plead for unlimited privacy and ignore the impact of said privacy. If you want unlimited privacy, at least have the balls to admit that this will allow free trade of CSAM, but also revenge porn, snuff-films and other things like it.
Some person that would sign that letter might be fine with video cameras in say a bank or some company building entrance but he is probably not fine with his own phone/laptop recording him and sending data to soem company or government without his consent.
So let's discuss where should the line be drawn, also if competent people in this domain are present let's discuss better ideas on preventing or catching criminals, or even for this method let's discuss if it can be done better to fix all the concerns.
What I am sure is that clever criminals will not be affected by this, so I would like to know if any future victim would be saved (I admit I might be wrong, so I would like to see more data from different countries that would imply the impact of this surveilance)
But it creates a infrastructure for all other kind of "criminal" data. I bet sooner or later governments want to include other hashes to find the owners of specific files. Could be bomb creation manuals, could be flyers against a corrupt regime. The sky is the limit and the road to hell is paved with good intentions.
I would really like to hear from people who do not sign this letter how they think about that.
With many packages this already happens in the search for drugs and weapons and I have no problem with that either.
It's the same reason I don't want police having any opportunistic information about me - both of these have an agenda, and so innocent people get pulled into scenarios they shouldn't be when that information becomes the unlucky best-fit of the day.
That Apple has even suggested this is disturbing because I have to fully expect this is their vision for every device I am using.
And then I expect from there, it's a race to the bottom until we treat our laptops like they are all live microphones.
I'm going to turn this around and say that those in favor of Apple's move: "Should the internet be a place where your every move is surveilled?" given that we have some expectation of privacy in real life.
You'd be surprised about the amount of packages that gets x-rayed in order to find drugs. But yes, you're 100% right that it's not all of them.
Let me ask you a counter-question. If I am able to draw child pornography so realistically that you couldn't easily tell, am I committing a crime by drawing?
That really depends on the law in the country where you're doing that. According to the law in my country, yes, you are.
None of this actually answers my question though, it's just a separate discussion. I would appreciate an actual answer.
Who’s talking about surrealistic drawings? We’re talking about actual material in real life, being shared by users and abusers.
To be clear, I’m not supporting surveillance, just stating facts.
This issue came before the US Supreme Court about a decade ago and they ruled that the depiction of a crime is not a crime so long as the depiction can in any way be called "art". In effect, any synthetic depiction of a crime is permitted.
However that ruling predated the rise of deep fakes. Would the SC reverse that decision now that fakes are essentially indistinguishable from the real thing? Frankly I think the current SC would flip since it's 67% conservative and has shown a willingness to reconsider limits on the first Amendment (esp. speech and religion).
But how would we re-draw the line between art and crime? Will all depictions of nudes have to be reassessed for whether the subject even might be perceived as underage? What about films like "Pan's Labyrinth" in which a child is tortured and murdered off-screen?
Do we really want to go there? This enters the realm of thought-crime, since the infraction was solely virtual and no one in the real world was harmed. If we choose this path, the freedom to share ideas will be changed forever.
Images can be illegal if all people are of age, but are portrayed as underage. Many historical dramas take legal advice about this when they have adult actors portraying people who historically married while underage by modern standards. (Ie the rape scene in BBC's The White Princess series.) This is why American porn companies shy away from cheerleader outfits, or any other suggestion of highschools.
I'm not sure I fully understand how society can be more relaxed with actual pedophiles than they are with cp material.
Personally it bothers me to see the focus around things that gross people out rather than the actual child abuse.
If the picture had no grounds to spread, it would likely not have been made—no incentive. As such, the fact that the picture is able to spread indirectly incentivises further physical abuse to children.
Yes, exactly.
It may even help prevent child abuse, because it may help pedophiles overcome their urges and not act upon it.
I'm not aware of any data regarding this issue exactly, but there are studies that show that general pornography use and sexual abuse are inversely correlated.
In effect, possessing such material may incentivize further production (and abuse), "macroeconomically" speaking. And I hate that evidently, yes, there is an economy of such content.
Maybe the same thing that makes this hard to understand about iOS will be what finally kills these absolutely wretched mobile OSes.
This is done client side because your data is encrypted in their cloud. It won't be done if you disable cloud sync. If you just keep your cp out of the cloud, you're fine.
In the USA guns are pretty freely available, relative to other countries. There is a huge amount of gun violence (including shooting at schools targeting children) yet every time major gun restriction legislation is introduced it fails, with one major reason being the 2nd amendment of the US constitution. This could again be amended, but sufficient support is not there for this to occur. What does this say about the US?
They have determined, as a society, that the value of their rights is worth more than all the deaths, injuries and pains caused by gun violence. A similar argument can be made regarding surveillance and child porn, or really any other type of criminal activity.
But how many apps only store the locally on the device versus sending data to the cloud, getting data from the cloud, or calling cloud APIs to get functionality that cannot be provided on device?
Having the power of a personal computing device is huge, but having a networked personal computing device is far greater.
Keeping everything on-device is a good ideal for privacy, but not very practical for networked computing.
The question is whether it is worse to do it on-device, than on the server. That’s what Apple actually announced.
I suspect Apple thought doing it on-device would be better for privacy. But it feels like a loss of control. If it’s on the server, then I can choose to not upload and avoid the technology (and its potential for political abuse). If it’s on my locked and managed mobile device, I have basically no control over when or which images are getting checked, for what.
> I can choose to not upload and avoid the technology
They are not scanning your entire photo library at rest.
Could they? Sure. But they’ve had the hardware to do this for years, so they could have done so silently at any time.
This entire saga has been one of poor messaging and rampant speculation.
Sure, in exactly the same way that the postal system, parcel delivery services, etc. allow it. But that's not to say that such things are unrestricted -- there are many ways that investigation and enforcement can be done no matter what. It's just a matter of how convenient that is.
It would also restrict CSAM a lot if authorities could engage in unrestricted secret proactive searches of everybody's home, too. I don't see this as being any different.
In fact there are a lot of heinous crimes out there some much worse than child porn IMHO. Singling out child porn as the reason seems like it's meant only to elicit an emotional response.
So, in a sense, you do consent to having those photos scanned by using iCloud. Maybe it's time for Apple to drop the marketing charade on privacy with iCloud, since iCloud backups aren't even encrypted anyway.
Would you prefer iOS submitted the photo's to their cloud unencrypted and Apple scanned them there? Because that's what the others are doing.
[1] https://www.kik.com/blog/using-microsofts-photodna-to-protec...
https://darknetdiaries.com/transcript/93/
If I were Kik, I would also write a blog post about using something like this. Many, many things point at Kik only doing the bare minimum though. (If you're the type who supports moderation, apparently they're already doing too much according to much of HN.)
https://www.theguardian.com/society/2019/dec/30/thousands-of...
Not doing anything opens the door to further abuse.
However, making this a legal requirement or deliberately manipulating a device to scan the entire content stored on that device without the user's consent or knowledge even, is extremely problematic, not just from a privacy point of view.
Such power can and will be abused and misused, sometimes purposefully, sometimes accidentally or erroneously. The devastating outcome to innocent people who have been wrongfully accused remains the same in either case (see https://areoform.wordpress.com/2021/08/06/on-apples-expanded... for a realistic scenario, for example).
The very least I'd expect if such a blanket surveillance system were implemented is that there were hefty, potentially crippling fines and penalties attached to abusing that system in order to avoid frivolous prosecution.
Otherwise, innocent people's lives could be ruined with little to no repercussions for those responsible.
Do strict privacy requirements allow crimes to be committed? Yes, they do. So do other civil liberties. However, we don't just casually do away with those.
If the police suspect a crime to have been committed they have to procure a warrant. That's the way it should work in these cases, too.
The better question would be: do you want an arbitrary person (like me) to decide whether you have a right to send an arbitrary pack of bytes?
Neither "society" nor "voters" nor "corporations" make these decisions. It is always an arbitrary person who does. Should one person surrender his agency into the hands of another?
Except in this case, a corporation (Apple) is making the decision relative to the sexual mores of modern Western society and the child pornography laws of the United States. It's unlikely this decision was made and implemented randomly by a single "arbitrary" individual. Contrary to your claim, it's never an arbitrary person.
And yes, I believe Apple has the right to decide how you use their product, including what bytes can and cannot be sent on it.
>Should one person surrender his agency into the hands of another?
We do that all the time, that's a fundamental aspect of living in a society.
But in this specific case, no one is forcing you to use an Apple phone, so you're not surrendering your agency, you're trading it in exchange for whatever convenience or features lead you to prefer an Apple product over competitors. That's still your choice to make.
Yes!!!
Actually I believe that in regards to "not doing anything open a different door to broader abuse" - no. Starting scans will lead to broader, and no tin foil hat needed.
If we compare 1-apple starts scanning for known hashes, not "looking at all your naked pics and seeing if you've got something questionable"... this is just looking for known / already created by others / historical things... by doing a scan for one thing - they open the pandoras box to start scanning for other things - and then they will be compelled by agents to scan for other things - and I believe that is broader, much.
Next month it will be scan for any images with a hash that matches a meme with fauci - the current admin has already stated that in their desire to stop 'disinformation' they want to censor sms text messages and facebook posts (assuming also fbk DMs and more).
There is a new consortium of tech co's sharing a list of bad people who share certain pdfs and 'manifestos' or something like that now right? Might as well scan for those docs too, add all them to the list.
What power this could lead to - soon the different agencies want scans for pics of drugs, hookers.. how about a scan for those images people on whatsapp are sharing with the black guy killing a cop with a hood on?
What happens when a new admin takes the house and white house and demands scans for all the trumped a traitor pics and make a list?
See this is where the encryption backdoors go.. and where is that line drawn? Is it federal level agencies that get to scan? can a local arizona county sheriff demand a scan of all phones that have traveled through their land/air space?
Frankly, public chats, public forums.. if you post kids or drugs or whatever is not legal there - then it's gonna get the men with guns to take note. What you do in private chats / DMs, etc - I think should stay there and not go anywhere else.
I don't like the idea that Msoft employees look at naked pics of my gf that are added to a pics folder because someone setup a win system without disabling one drive. So I don't use one drive and tell others to not use it - and not put pics of me there or on fbk or tictoc.
For all those people that have nothing to hide - I feel sorry for you - but wonder if your kids/grandkids should have thousands of agents looking into their private pics just to make sure there is nothing not legal there.
so would these scans get nudes sent through whatsapp? That would kill the encryption thing there kind of.
Would this scan get a cach if someone was using a chat room and some asshat posted something they shouldn't - and every person in the chat got a pic delivered to their screen. so many questions.
I also question what the apple scans would scan as far as folders and what not.. would it scan for things in a browser cache? like not purposefully downloaded.. if someone hit a page that had a setup image on it - would that person now be flagged for inspection / seizing?
If they are working with nice guys in Cali that just want to tap people on the shoulder and have a talk with people - will they send flagged notices to agents in other places who may go in with guns drawn and end up killing people?
I'm sure many people are fine with either outcome - I think there is a difference between someone surfing the web and someone who coerces real world harm, and not all those who surf the web deserve bullets to the chest, and there is no way to control that.. well maybe in the uk where cops aren't allowed to have guns maybe.
My parents gave me privacy and treated me with respect when I was a child. Now I'm an adult, and in a way it's like I have less privacy than when I was a kid. And the entities violating my privacy have way more power than my parents.
I want to continue working with technology, but how can I make mass consumer goods (i.e. apps) without being a user myself? These moves are going to slowly force me out of technology, which is sad, because creating with programming is my favorite activity. But life without some semblance privacy is hardly life.
Here's to a slow farewell, Apple! It was a good run.
That is a very accurate representation of how I feel about this, too. I enjoy building apps, but I don't know that I can keep using these devices.
I was looking forward to upgrading to the new hardware in the fall, but now I'm not sure I can stomach the implications of buying a new device that may at any point start policing what I do far beyond what I'd accepted at the time of purchase.
This, of course, ignores how a lot of child abusers are underage themselves and know the victim,[2] and that the prosecutors are committing the same crime as the prosecuted in the case of CP, and that, in too many cases, the content in question is impossible to call malicious if it is seen in context.[3]
[1] https://columbiachronicle.com/discrepancy-in-sex-offender-se...
[2] https://web.archive.org/web/20130327054759/http://columbiach...
Seems unclear what the alternative is now. The Linux phones I’ve looked at have a lot of catching up to do.
After reading OP, my understanding had been that this update will cause _all_ photos on Apple devices to be scanned. However, the above quote from Apple's statement seems to indicate that only photos uploaded to iCloud Photos are scanned (even though they are technically scanned offline).
This doesn't invalidate any of the points people are making, but it does seem the update does not directly affect those of us who never stored our photos “in the cloud”.
https://morningstaronline.co.uk/article/w/apple-drops-plans-...
This sounds like them trying to find a way to encrypt your data and remove the fbi from having a “what about the children excuse”. They scan the image on upload and then store it on iCloud and encrypt it.
It’s of course a slippery slope but the FBI has been trying to have back doors everywhere since forever.
A stark change since Apple/FBI.
It doesn't matter. This is the wrong choice, and everyone should rebuke and abandon Apple for this.
Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China.
Apple has at this point already admitted this is within is capability. So regardless of what they do now, the battle is already lost. Glad I don't use iThings.
Good job it's ebay 80% off fees this weekend here in the UK.
This system has so much potential for abuse with very little upside.
[0]: https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
https://www.rollingstone.com/politics/politics-news/apple-ce...
The hypocrisy levels are vomit inducing...
From what I understand, only to Chinese customers's data and messages (bad enough, sure, but not as bad as you say).
In some of those countries same-sex sex is punishable by death.
I think the US Govt (and foreign) would actually send Apple tens of thousands of NeuralHashes a week. Why would they limit themselves? False positives are "free" to them.
Correct, just look at the incentives when it comes to handling sniffer dogs.
They don't (publicly announce that they) scan things on my device.
I’m not trying to minimize the danger of that slope. But as someone who is interested in the particulars of what Apple announced specifically, it is getting tiresome to wade through all the comments from people just discovering that PhotoDNA exists in general.
"Its just when you upload to icloud or recieve an iMessage" they say. BUT the software's on your device forever. What about next year? What about after an authoritarian goverment approaches them? By 2023 it might be searching non-uploaded photos.
You can always not use cloud tech like PhotoDNA but you can't not use software BUILT IN to your device. Especially when its not transparent.
It did not sound like they could retroactively add additional hashes and decrypt something that already was uploaded. They could theoretically add something to the list of hashes and catch future uploads of it but my understanding was they cannot do this for stuff that has already been stored.
> ...the system performs on-device matching using a database of known CSAM image hashes provided by NCMEC and other child safety organizations. Apple further transforms this database into an unreadable set of hashes that is securely stored on users’ devices.
>... The device creates a cryptographic safety voucher that encodes the match result along with additional encrypted data about the image. This voucher is uploaded to iCloud Photos along with the image.
That's a very simple software update.
Every year iOS gets more images the automatic tagging supports (dogs, shoes, bridges, etc). And if you add a friend's face to known faces, it'll go and search every other photo for that face.
It sounds absolutely trivial to re-scan when the hash DB gets updated.
1. This is a serious attempt to build a privacy preserving solution to child pornography.
2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it.
However:
Child pornography and the related abuse is widely thought of as a massive problem, that is facilitated by encrypted communication and digital photography. People do care about this issue.
‘Think of the children’ is a great pretext for increasing surveillance, because it isn’t an irrational fear.
So: where are the proposals for a better solution?
I see here people who themselves are afraid of the real consequences of government/corporate surveillance, and whose fear prevents them from empathizing with the people who are afraid of the equally real consequences of organized child sexual exploitation.
‘My fear is more important than your fear’, is the root of ordinary political polarization.
What would be a hacker alternative would be to come up with a technical solution that solves for both fears at the same time.
This is what Apple has attempted, but the wisdom here is that they have failed.
Can anyone propose anything better, or are we stuck with just politics as usual?
Edit: added ‘widely thought of as’ to make it clear that I am referring to a widely held position, not that I am arguing for it.
https://transparencyreport.google.com/youtube-policy/feature...
Apple: hey govt, here's some probable cause.
Govt: warrant, search, arrest
User: prosecuted
Having said that, there is an enormous amount of misinformation and fear-mongering about a pretty tame change. This seems like so much ado about very close to nothing.
a) They optionally scan messaged photos for nudity using a NN if the participants are children and in a family (the account grouping), and the group adult(s) have opted in, giving children warnings and information if they send or receive such material. A+++ thumbs up.
b) They scan photos that you've uploaded to iCloud (available at photos.icloud.com, unencrypted -- in the E2E sense, effectively "plaintext" from Apple's perspective -- etc) for known CP hashes. Bizarrely Apple decided to scan these on device as well, causing 99% of the outrage and confusion, yet every major cloud photo service in the world does such checks for the same reason, whether you have the photo set to private or not, and presumably Apple decided to do it on device simply as free distributed computing, taking advantage of hundreds of millions of high performance chips, but most importantly as a PR move demonstrating that "Apple Silicon helps with Child Safety", etc.
That's it. Various "this is a harbinger of doom and tomorrow they're going to..." arguments are unconvincing. This does absolutely nothing to break or subvert E2E encryption or on device privacy.
EDIT: The moderation of this comment has been fascinating, going to double digits, down to negatives, back up again, etc.
https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
So now they’re doing it on device too. This feels like it’s putting in place the foundation to scan all offline content.
Leave my kids alone.
If they want to share photos of themselves naked, it's none of anyone's business except them and maybe me (maybe), certainly not a huge American corporation.
Neither me or my kids have iPhones, but as others have observed, I have no illusions that Google will follow suit. Our options are becoming pretty limited at this point.
That would get a lot of people nervous. Let alone anyone smart who thinks through the implications here of how far the line is being pushed on how public your phone is.
I have never once in my life thought about activating an automatic back up to cloud feature on any phone I have ever owned, for a single second. So yes, it is hella different. This is for all the same reasons I backup personal data only to my NAS and use cloud accounts for generic shit like purchased music backups and nothing more.
I prefer losing all my photos if my phone is pickpocketed in between backups to having a public record of everything I ever photographed. Am I the 0.00000001% or something? I didn't even realize I was the odd man out, honestly.
I don't see a reason to do this, other than to either scan all images, or claim that iCloud is e2e in the future.
And of course they went with the protection of children argument, which is bullshit. Apple gets paid by its users and should have no other interests than to get paid as much money as possible, regardless of who pays them.
Do it in the cloud just like every other service does. None of this anger would have happened if they just kept it in the cloud, and I truly can not fathom how this made it this far. I would peg overwhelming odds that they abandon the on device idea as it makes no sense and has brought incredible ill will.
We have no idea about the hash collisions. When talking about whole world, 2^256 isn't a big enough space.... even if they're using 256 bits.
And how dare anybody criticize this - criticism is tantamount to being for child porn. (Then again, that's why it was chosen. We'll soon see other things 'forbidden'.)
Clearly you do not understand the full ramification of what is happening here.
As an Android user I'd love to gloat, after all Apple have really had the upper edge on privacy so far, and their users have not been shy about telling us. Again and again.
However any pleasure would be as short lived as peeing your pants to keep warm in winter, because if Apple proceeds, Google is bound to follow.
A user monitoring system like this is just ripe for abuse of the most horrific kinds. It must die.
This is this a first step to "Detective in your Pocket", cloaked intentionally, or not, by a well-meaning objective. An objective we can all support. If you wanted to put in a thin wedge on distributed surveillance, where better to start? As pointed out CSAM filtering/scanning is already done so that’s not the issue here. There’s a big debate to be had, and being had, on the upsides/downsides and benefits/dangers of AI and false positives. That’s a huge issue in itself; but that’s not the biggest concern with this move. If Apple pushes on with this it’s a clear signal that they wish to march us all to a new world order with Distributed Surveillance, as a Service. A march in step with the drumbeat of your increasingly authoritarian (or if you are lucky or more generous, safety conscious) government.
I have signed the letter to express my very strong personal concerns but also as a CEO of a company that takes CSAM seriously and seeks to provide solutions, in search, without surveillance.
"Why didn't you tell me this was going on?" "You're simply too stupid to handle the idea that your betters might occasionally be untrustworthy"
Wait, no, that's not the argument ...
There is a difference between selling your data to the highest bidder through a stalker capitalism ecosystem and giving governments carte blanche access.
I am not at all advocating for the latter, but if you are fighting that battle, CP is not the hill to die on.
They were already sold into the Apple ecosystem with the iPhone 12's, M1 Macs and iPad Pros. They are going to have a hard time moving to another platform.
Best part? Apple is a huge customer of Google Cloud for storage so you can now tell Google about all the files on your iCloud account. [0]
'With privacy in mind.' /s
[0] https://appleinsider.com/articles/21/06/29/apple-is-now-goog...
While moderating CP distribution and storage is obviously the right thing to do, I do not think this approach will be a worthwhile endeavor for apple and governments.
Let me explain: imagine you are bad guy with bad stuff on your iphone, and you hear apple will be scanning your phone. What is the next logical thing you would do? Migrate your stuff to something else, obviously. Encrypting a usb stick does not require a high degree of technical skill [1]; neither does running tor browser.
So I am thinking 3 things:
1. This is not about CP or doing the right thing, but rather apple bowing to government/s pressure to create a half-ass backdoor to monitor and squash dissidents.
2. Apple and government/s are incompetent and do not realize that criminals are always one step ahead.
3. Most likely, some combination of the above - government/s have demonstrated they are willing to go hard on dissidents on the personal electronics front [2], not realizing that they will only mitigate, not exterminate, the dissent they fear so much.
For the average joe, I would say this - your privacy is effectively gone when you use an electronic device that comes with closed-source code pre-installed.
For the benevolent dissidents - there are many tools at your disposal [3, 4].
Likely next iteration - governments / courts / cops compel suspects to hand over passwords and encryption keys over to prosecutors. It looks like it already started [5, 6], so act accordingly.
[1] https://www.veracrypt.fr/code/VeraCrypt/
[2] https://www.washingtonpost.com/investigations/interactive/20...
[3] https://files.gendo.ch/Books/InfoSec_for_Journalists_V1.1.pd...
[4] https://www.privacytools.io/
That is like the USPS opening every letter and scanning what is inside. Even if it's done with machine learning, that is absolutely not okay, no matter what it is for.
Perhaps I missed it, but does anywhere on this letter mention that that both of these features are optional?
CSAM depends on using iCloud Photos. Don’t rent someone else’s computer if you don’t want them to decide what you can put on it.
Content filter for iMessages is for kids accounts only, and can be turned off. Or, even better: skip iMessages for Signal.
Very smart people are not getting this wrong.
Wrong [1]. It's even in the first line of the document which you apparently didn't even read:
CSAM Detection enables Apple to accurately identify and report iCloud users who store
known Child Sexual Abuse Material (CSAM) in their iCloud Photos accounts
This doesn't mean I'm supporting their new "feature".1. https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
Why is this the obvious conclusion?
We are not getting this wrong. Apple is taking an egregious step to satisfy the CCP and FBI.
Future US politicians could easily be blackmailed by the non-illegal content on their phones. This is a jeopardy to our democracy.
The only reason this was announced yesterday is because it was leaked on Twitter and to the press. Apple is in damage control mode.
This isn't about protecting children. It's about control.
Stop defending Apple.
When the device uploads an image it’s also required to upload a cryptographic blob derived from the CSAM database which can then be used by iCloud to identify photos that might match.
As built at the moment, your phone only “snitches” on you when it uploads a photo to iCloud. No uploads, no snitching.
We know that every other cloud provider scans uploads for CSAM, they just do it server side because their systems aren’t E2E.
This doesn’t change the fact that having such a scanning capability built into iOS is scary, or can be misused. But in its original conception, it’s not unreasonable for Apple to say that your device must provide a cryptographic attestation that data uploaded isn’t CP.
I think Apple is in a very hard place here. They’re almost certainly under significant pressure to prove their systems can’t be abused for storing or distributing CP, and coming out and saying they’ll do nothing to prevent CP is suicide. But equally the alternative is a horrific violation of privacy.
Unfortunately all this just points to a larger societal issue. Where CP has been weaponised, and authorities are more interested in preventing the distribution of CP, rather than it’s creation. Presumably because one of those is much easier to solve, and creates better headlines, than the other.
US politicians should not be using normie clouds full stop. This is a risk and always has been.
It's like telling an average person to use GNU/Linux for their desktop OS and then watching them struggle to get printing to work well (I have been through this).
We have to assume given the pressure Apple has been under to build a surveillance tool like this that any "abuse cases" such as identifying outlawed LGBTQ content is in fact exactly what this tool was built for.
Apple have already proven their willingness to bend the knee to the CCP with actions such as App Store removals. I almost can't blame Apple for this because in all likelihood if Apple refuses to cooperate they will eventually lose market access. Couple this with the fact today Apple is seeing increasing pressure from western governments to surveil and censor "hate speech" and "misinformation" they've probably reluctantly accepted that sooner or later they will have no choice but to spy on their users.
What I'm trying to say is that Apple isn't the problem here. My guess is Apple's engineers are smart enough to know this technology can and likely will be abused. They're also probably not that interested in spying on their customers as a private company in the business of convincing people to buy their communication devices. Apple did this because governments have been demanding this. And in recent years these demands have not only been coming from the CCP and other authoritarian regimes, but also from governments in their primary markets in the West.
The only way we can fight this is by demanding our politicians respect our right to privacy and fight for technologies like e2e encryption on all of our devices.
I don't want to be overly negative, but realistically this isn't going to happen. Most people who use Apple's devices don't understand encryption or the risks content scanning technology present. And even if they did, no one is going to vote for a representative because of their stance on encryption technology. It seems almost inevitable that the luxury of private communication for all will eventually be a thing of the past.
I'm just glad I know how to secure my own devices.
[1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
But announcing both features in the same post makes it inevitable that they get conflated, e.g. “Apple’s machine learning will send suspected child porn-like images from your iMessages to iCloud, where it will be reviewed and possibly sent to the police”. Apple obviously knows this — so them being ok with that raises some serious eyebrows, as if they’re quietly setting the groundwork to make that a reality.
[0] https://www.businessinsider.com/apple-fbi-icloud-investigati...
I don’t see how the article you linked to explains how Apple can “scan iCloud” for the police. What do you mean? It seems like they just hand data over for a specific warrant related to individual users.
This is the War on General Computation you have been warned about, and its good to reiterate: "You ( and I mean you as an Individual and you as a Company ) you are either with us, or against us"
He was canceled, but he still regularly updates his personal website: https://stallman.org/
chiming is on this would just give the cancel mob more ammunition
Thinks like this must to be stopped! Customers shall not buy anything from companies which are hostile. And laws against these usage need passed. As far as it looks, the laws in Europe are in place and prevent this currently. But just currently, we've seen how companies like Apple push the boundaries. We as humans behave totally irrational, we complain about inhumane working conditions at Amazon and then we order the next item. We complain about a golden prison from Apple and buy the next iPhone. We should change?
While this is not inevitable, I see a strong, perhaps overwhelming public response as being the only thing that will prevent it, and I do not see that response happening.
By today, it's pretty clear than privacy is not the top priority of most people. See how much data people are giving fb/google every second...
The louder people are about this, the more it hurts and the more likely the policy is reversed.
if the policy is not reversed, then at least the community has been loud enough that people took notice and understood that this is happening, giving them a chance to vote with their wallet; for most people what happens on a computer or a phone is a complete mystery.
I think that earnest acceptance of “well, it’s for a good cause” style arguments indicates a severely stunted ability to generalize: either to generalize applications of the technology (it works on any proscribed content, not just stuff people generally agree is bad) or to generalize outcomes of this kind of corporate behavior (Apple will continue to actively spy on their customers as long as they can come up with a tenuous justification for it).
It is also not quite clear if Apple is taking a moral or legal stand here. If it is legal then this could in the future open doors to:
- Scanning for other types of illegal content
- Scanning for copyrighted content (music, images, books, ...)
- Scanning your iCloud files and documents
- Scanning emails to make sure you are not doing anyting illegal
If it is morally driven and Apple wants to really take a stand against any CSAM material on its devices, they would really have to do it at a system level, monitoring all data being transferred (including all communications, all browsing etc) so this could just be the first step.
A moral-based agenda would be much easier for broader public to accept, while a legal-based agenda could lead to other kinds of privacy-intruding consequences. And even a moral-based agenda would still be a precedent as ultimately we do not know what are Apple's "moral values" and what would it be ready to intrude user's privacy over in the future?
Seems like a slippery slope for a company to take, any way you turn it, specially if privacy is one of your main selling points.
Another thought: if we as a society agree that CSAM is unacceptable, why not globally prevent it at an internet router level? edit: jetlagged... we can't because data is encrypted. It has to be at client level, pre-encyption.
Really? What is the goal?
It's not to prevent child abuse, since passively looking at images is not, per se, abuse.
It's also not to limit the making of child pornography, since this will only search for already existing and already known images that already exist in government databases.
If you make new images that are not yet in said databases, you're fine.
I'm not sure what the actual goal is (project a virtuous company image, maybe?), but the result could very well be the opposite of what people think.
This feature absolutely will be used for human rights abuse by countries like China, just like they have asked Apple to abuse their platform in the past. Why? Because those abuses are legal there, and capitulation will be the only way those governments will allow them continue to sell in their lucrative marketplace.
https://www.washingtonpost.com/technology/2021/08/05/apple-c...
That seems even worse. In the US we have this terrible situation where it might be perfectly legal for two 17 year olds or a 17 and an 18 year old to have sex with each other but if they sext then they're engaging in child pornography which is a huge federal crime. But it hasn't been a problem until now because it's very hard to enforce. But it looks like Apple is now going to take part in enforcing that law. It'll be tattling to the parents rather than law enforcement but I still think that's terrible.
1. The law presumes we are all innocent until proven guilty.
2. We have the right against self-incrimination.
Pervasive surveillance like this starts with the presumption that we are all guilty of something ("if you are innocent, why are you scared of such surveillance?"). The right against self-incrimination is linked to the first doctrine because compelling an accused to testify transfers the burden of proving innocence to the accused, instead of requiring the government to prove his guilt.The point in bitching to Apple isn't to make them change, but to bring attention to privacy issues to the hoi polloi. Cleaning up your own privacy act is the main lesson.
Maybe the only logical place to end up is a dedicated Chromebook in guest mode for financial transactions, air-gapped workstation to do artistic or other useful things, rarely-used dumbphone, get out more among physical people.
“ These features are coming later this year in updates to iOS 15, iPadOS 15, watchOS 8, and macOS Monterey.*”
They've always been able to launch surveillance software on a whim apparently. This is proof.
https://en.wikipedia.org/wiki/List_of_open-source_mobile_pho...
What Apple has done here is both way more complicated and way more visible than necessary, while being less useful to a government. The slippery slope and capability to exploit is cloud storage.
Just don't store any data on iCloud. Seems simple enough. Yeah sure, we can make conspiracy theories and all, but based off of what was officially announced I'm not understanding all the hysteria.
Once they have the mechanism in place to censor and report content. They will for sure be requested to use this. For terrorism, hate speech, etc until it's so blurry until it's absolutely limitless :(
“ Apple's proposed technology works by continuously monitoring all photos stored or shared on a user's iPhone, iPad or Mac, and notifying the authorities if a certain number of objectionable photos is detected.”
From: https://www.apple.com/child-safety/pdf/Expanded_Protections_...
“ Before an image is stored in iCloud Photos, an on-device matching process is performed for that image against the unreadable set of known CSAM hashes. “
I think it only does this before iCloud upload.
1) its only scanned on upload to iCloud, so if you don't upload then its not scanned
2) (per another article, https://techcrunch.com/2021/08/05/apple-icloud-photos-scanni...): Most cloud services — Dropbox, Google, and Microsoft to name a few — already scan user files for content that might violate their terms of service or be potentially illegal, like CSAM.
So you really can't opt out unless you avoid all cloud photos
are you going to have a huge scandal every time they turn on a new “feature”?
The alternative is to not start scanning your device in the first place and getting the foot in the door, because once it’s open it’s really hard to close.
[0] https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute
Personally, for my iPhone photos, I have my phone setup to upload every picture I take to Apple iCloud, Google Photos, and Microsoft OneDrive, so I gave up on photo privacy many years ago.
Of course the civil disobedience way of dealing with this would be to find an entirely safe image which matches the hash so that every website can safely embed such an image and show the utter futility of the idea.
The best counterargument I've seen to that is that Apple is lying and it's not limited to Apple Cloud, unlike Google. However, no one yet has been able to substantiate that claim.
[1] https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
Apple also removes LGBT based applications in countries where they're illigal, to continue doing business. This demonstrates that Apple complies with the demands of foreign governments, that they value money over anything else.
So Apple, a company that complies with governments committing human rights violations (Including the U.S), forces everyone to have an image scanner that looks through their private images and documents to find content Apple has deemed objectionable, with the sources of that content supposedly being from these governments.
FBI: Hey apple, here's some new hashes for images that are bad, let us know who has them. You just have to trust us, no way that we would ever put political imagery critical of the government in that database. But you can't prove it even if we did.
Remember, this is the FBI that flaunts federal court orders, breaks the law, and no one is ever held accountable. https://youtu.be/oy3623YRsMk
My suspicion is that the FBI finally had enough of Apple not complying with their encryption standards and have done some work behind the scenes to make various individuals at Apple's lives difficult. So they're implementing this to appease the feds.
There was a thread on HN here not too long ago with the FBI stalking and threatening pentesters that wouldn't join them. No doubt they're doing the same to big companies that are making their "jobs" harder.
The most positive spin I can put on it is that it has become clear behind the scenes that NCMEC and partners have put enough pressure on Congress that Apple believes that on-device scanning for CSAM content will be soon be required by federal law, and this is their attempt to define the parameters in as privacy-preserving a way they can before the actual legislative language is drafted and can't be changed.
Even if all of that is true, I don't think this was the best way to do it and it is a huge own-goal to concede ground before there's even been a public debate about it.
Maybe or maybe they think that good computing devices are valuable to everyone now and that repressive laws can be changed eventually as they have in many countries, and denying good computers to people who also live with repression makes their lives worse, not better.
For several years now politicians have been asking for "exceptional access for law enforcement" to backdoor encryption. In Europe there's been a number of laws passed recently which violate privacy also.
This is just Apple getting ahead of future legislation so that they can be the ones who get the power and money from every government agency turning to them first whenever they want to monitor and punish their citizens.
> Meanwhile, the computer scientist who more than a decade ago invented PhotoDNA, the technology used by law enforcement to identify child pornography online, acknowledged the potential for abuse of Apple's system but said it was far outweighed by the imperative of battling child sexual abuse.
> "Apple's expanded protection for children is a game changer," John Clark, the president and CEO of the National Center for Missing and Exploited Children, said in a statement. "With so many people using Apple products, these new safety measures have lifesaving potential for children."
I really just hope they revert this plan.
Then you use the modern computer your company provides strictly for business purposes.
Strategically, apple showed its cards. But then again, that was bound to happen too ;-)
No normal citizen will be allowed to run for president anymore. I think it's time for a true movement.
Even if Apple continues down this path, perhaps the backlash will make techies abandon them. That would have a notable effect on their ecosystem.
The author of this Tweet has a point and made it clear all along for a long time.
This though, this will be the nail in the coffin with my 25 year relationship to Apple. I probably wouldn't even have batted an eye at it to be honest, iff, Apple hadn't been selling me on the idea that their platform is "private and secure." But... they have... And this has made it quite clear, they will absolutely destroy that security/privacy the moment they want/need to. So I have been paying, a hefty premium, to be lied to and that makes me fucking cross. I have previously supported Apple because it seems like they typically do "the right thing" but this is so fucking insane to me I have to permanently question the judgement of those in charge.
Do not sell privacy and security if you're going to completely violate that security and privacy.
In 25 years or less this bullshit will be made illegal, because there is ZERO chance nefarious actors won't learn how to create benign images that match the hash of a heinous photo to destroy people. I can almost guarantee, right now, nation-state sponsored hackers and affiliated groups are attempting to get those hashes and do exactly that. It's just too fucking easy to manipulate once you're in and has absolutely zero chance of being detected once you're generating the hashes until too many lives are ruined.
May hell have no mercy for the souls who made this...
Boy. I was so wrong. I fell for the Marketing and it made sense at the time “Their business is selling hardware and services, not ads. Ofcourse they are privacy advocates”.
Pass laws and legislation. I admit I was wrong and it’s refreshing to see this whole thing unfold before my eyes. It just solidified my opinion about open source hardware.
But do you seriously think this isn’t going to be the standard for Android, Windows, ChromeOS, OSX, etc coming at degrees of time or implementation?
I know all the Android people are just thinking “I can root” or “I’ll run Lineage” which is well and good but relatively no one else will.
Stomping your feet and saying No More Apple For Me is not a winner here. It needs to be worse than that for them. What that looks like? I’m just as clueless as anyone else.
What is broken about the M1?
... the alerts go to Apple for human review. You think their human review won't notice a garbled nonsense picture triggering a false positive?
Chinese Government: Here is the NeuralHash for some child abuse imagery, please scan this user's phone and tell us if it's found.
Apple: Sure we found it.
Chinese Government: this user has unpermitted winnie the pooh memes. Send them to an internment camp.
Apple: Sure we found it.
Chinese Government to some western company/instititution: We have detected unacceptable behavior from your employee/student/client/vendor. Please cancel them, or we will stop funding you.
Modi's Indian Government: This opposition leader is criticising us too much. Send him a child abuse imagery and ask Apple / Google to scan for it on his phone.
Apple / Google: We found it!
Modi's Indian Government: Let the defamation begin!
Context:
- Evidence found on a second Indian activist’s computer was planted, report says - https://www.washingtonpost.com/world/2021/07/06/bhima-korega... ]
- Pegasus Snoopgate - https://www.youtube.com/watch?v=Ppt3FIV2itQ
We detached this subthread from https://news.ycombinator.com/item?id=28086140.
Amazon: Don't forget us too! [0]
To Downvoters: Are you telling me that this is false? Even worse for the Gmail users. [1] I guess the outrage was already overdue with these tech giants.
[0] https://appleinsider.com/articles/21/06/29/apple-is-now-goog...
[1] https://www.theverge.com/2014/8/5/5970141/how-google-scans-y...
There are already places in this world, where a couple can be arrested for kissing in public. I suspect that the folks enforcing those laws, would have some real interest in this capability.
Not to mention nations (many in Africa, but there are also Eurasian nations), where homosexuality is banned (or even considered for death penalties). If your phone has a picture of two men (or women) embracing, it could cause nightmares.
The main beef people seem to have here is the slippery slope argument. Binary choices are nice, I agree - but almost always they obscure a complex surface that deserves nuance.